Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Miguel Falé

#21388of 53,635
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-21105
6.1
2024-04-04
Esri · Esri Portal For Arcgis · CVE-2024-25709
**Name of the Vulnerable Software and Affected Versions** Esri Portal for ArcGIS versions 10.8.1 through 10.8.1 – 1121 **Description** The issue is a stored Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, potentially executing arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. **Recommendations** For Esri Portal for ArcGIS versions 10.8.1 through 10.8.1 – 1121, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-15396
5.4
2024-01-09
Synopsys · Synopsys Seeker · CVE-2024-0226
**Name of the Vulnerable Software and Affected Versions** Synopsys Seeker versions prior to 2023.12.0 **Description** The issue is a stored cross-site scripting vulnerability that can be exploited through a specially crafted payload. **Recommendations** For versions prior to 2023.12.0, update to version 2023.12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable components until the update can be applied.